Plaintext stays client-side in normal share workflows
Text, environment-variable payloads, files, share passwords, and private decryption keys are handled in the browser, not by the PrivShare server.
PrivShare security
PrivShare is designed to minimize the amount you have to trust PrivShare. These pages document what the app protects, what it does not protect, and how a technical user can inspect the browser traffic.
PrivShare is an independent project maintained by Yash Aggarwal.
This first security baseline uses named individual accountability. It does not present PrivShare as operated by a registered company.
Start with the architecture and threat model, then verify the implementation boundary in your own browser.
These claims are scoped to implemented share workflows and current repository evidence.
Text, environment-variable payloads, files, share passwords, and private decryption keys are handled in the browser, not by the PrivShare server.
The cryptography page documents algorithms, parameters, encodings, key transport, and server-visible metadata.
The threat model calls out compromised devices, malicious browser extensions, copied recipient plaintext, full URL disclosure, and malicious delivered JavaScript.
Security researchers can test their own accounts and test shares, then report issues to security@priv-share.com.
The absence of these claims is intentional. They are future work or require owner-side verification before public use.